Back to skill

Security audit

Zoom

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Zoom integration that uses ClawLink OAuth to manage meetings, webinars, recordings, and related Zoom workflows, with some caution needed around sensitive account access and write-action confirmation.

Install this only if you trust ClawLink to broker OAuth access to your Zoom account. Review the Zoom permissions granted during connection, especially for recordings, registrants, user settings, and ZRA/conversation data. For any create, update, registration, or delete action, require a preview and explicit approval before execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly states that all write operations require explicit user confirmation and recommends a preview/confirm workflow, but the examples show direct invocation of write tools such as meeting creation and webinar registration. This inconsistency can train an agent or user to bypass the intended safety gate, increasing the risk of unauthorized or unintended state-changing actions in a live Zoom account.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.